Vikunja

Vikunja

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 28.08.2026 16:51:48
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorize...

  • EPSS 0.35%
  • Veröffentlicht 28.08.2026 16:40:27
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an att...

  • EPSS 0.27%
  • Veröffentlicht 28.08.2026 16:38:38
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to 0 to POST /a...

  • EPSS 0.31%
  • Veröffentlicht 28.08.2026 16:36:57
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplicate beneath an...

  • EPSS 0.36%
  • Veröffentlicht 10.07.2026 13:57:59
  • Zuletzt bearbeitet 10.07.2026 17:56:00

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 10.04.2026 16:12:27
  • Zuletzt bearbeitet 17.04.2026 22:03:51

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement for custom project background routes is method-confused. A token with only projects.background can successfully delete a project ba...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 10.04.2026 16:10:39
  • Zuletzt bearbeitet 17.04.2026 21:49:40

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON metadata inside the import zip instead of the actual decompressed file content leng...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 10.04.2026 16:08:50
  • Zuletzt bearbeitet 17.04.2026 21:56:20

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles contain...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 10.04.2026 16:07:07
  • Zuletzt bearbeitet 17.04.2026 21:56:40

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters. When rendered by goldmark and san...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.04.2026 16:05:57
  • Zuletzt bearbeitet 17.04.2026 21:57:24

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current time. By creating a repeating ...